The ExpressRoute routing domain for reaching Azure VNets from on-premises networks over private addressing. Unless IPsec or MACsec is layered on, the traffic travels unencrypted.
Also called Azure private peering.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Private peering in context, with comparison tables and the common traps.
Terms in this definition
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
Related terms
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- Default route
The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
- DMZ
A firewalled buffer network on premises that sits between the outside world and the core network. Microsoft Learn suggests ending ExpressRoute Microsoft peering there, while private peering lands on the core.
- ExpressRoute circuit
The logical link between on-premises and Microsoft, provided by a connectivity partner or through ExpressRoute Direct. A service key identifies it, and it carries both Microsoft and private peering.
- Use Azure Private IP Address
Setting this on a VPN connection makes the gateway's private IP the tunnel endpoint, which is how IPsec runs over ExpressRoute private peering. Compatibility between route-based gateways and policy-based devices is a separate matter it doesn't solve.